PACS modification to incorporate LACS authentication
Abstract
A method of integrating a logical access control system with a physical access control system is disclosed. A soft token is received at a hardware accessory from a client device of a user. The soft token includes a payload. The payload includes information about the user that is stored in a user profile of the logical access control system. Based on a verifying of the soft token using a certificate extracted from a trust store of the hardware accessory, the information about the user that is included in the payload is parsed. Based on the information about the user satisfying one or more access criteria of a reader associated with a physical access control system, the reader is triggered. The triggering includes emulating a transaction associated with the physical access control system.
Claims
exact text as granted — not AI-modifiedThe invention claimed is:
1 . A system comprising:
one or more computer processors; one or more computer memories; a set of instructions incorporated into the one or more computer memories, the set of instructions configuring the one or more computer processors to perform operations, the operations comprising, at a hardware accessory: receiving a soft token from a client device of a user, the soft token having been generated or received at the client device based on an accessing of a logical profile of the user by the client device via one or more services of a logical access control system, the soft token including a payload, the payload including information about the user that is stored in the logical profile, the soft token being a JWE token that is decrypted using a private RSA key stored in a secure element of the hardware accessory; based on a verifying of the soft token using a certificate extracted from a trust store of the hardware accessory, parsing the information about the user that is included in the payload; and based on the information about the user satisfying one or more access criteria of a reader associated with a physical access control system, triggering the reader, the triggering including emulating a transaction associated with the physical access control system.
2 . The system of claim 1 , wherein the information about the user includes a role of the user.
3 . The system of claim 1 , wherein the information about the user includes a credential of the user, the credential associated with a smart card of the physical access control system, the smart card having been assigned to the user.
4 . The system of claim 3 , wherein the emulating of the transaction includes sending the credential to the reader over a secure connection in a format that is compatible with the physical access control system.
5 . The system of claim 4 , wherein the secure connection is a near field communication (NFC), Bluetooth connection, or other wireless connection.
6 . The system of claim 3 , wherein the credential is sent to the reader as a single object.
7 . The system of claim 6 , wherein the single object is a Secure Identity Object (SIO).
8 . The system of claim 1 , wherein the transaction is a Seos transaction.
9 . The system of claim 1 , wherein the soft token is a JWT token.
10 . The system of claim 1 , wherein the operations further comprise:
creating a logical association between the reader, the hardware accessory, and a client ID of the hardware accessory during a configuration phase, the creating of the logical association including simultaneously provisioning a public certificate, generating the private RSA key, and registering the client ID, the logical association resulting in the hardware accessory being represented as an element of a LACS, the hardware accessory being an element of a PACS; and decrypting the JWE using the private RSA key.
11 . The system of claim 10 , wherein the registering of the client ID for the hardware accessory includes using a dynamic Open ID Connect client registration POST request, the POST request including a scope definition that defines a new scope or an existing scope, the scope definition allowing a client application to request a soft token based on the scope definition.
12 . The system of claim 10 , further comprising communicating the logical association to the client device for transmission to the logical access control system for storing in a persistence layer of the logical access control system.
13 . A method comprising:
receiving a soft token from a client device of a user, the soft token having been generated or received at the client device based on an accessing of a logical profile of the user by the client device via one or more services of a logical access control system, the soft token including a payload, the payload including information about the user that is stored in the logical profile, the soft token being a JWE token that is decrypted using a private RSA key stored in a secure element of a hardware accessory; based on a verifying of the soft token using a certificate extracted from a trust store of the hardware accessory, parsing the information about the user that is included in the payload; and based on the information about the user satisfying one or more access criteria of a reader associated with a physical access control system, triggering the reader, the triggering including emulating a transaction associated with the physical access control system.
14 . The method of claim 13 , wherein the information about the user includes a role or a group of the user.
15 . The method of claim 13 , wherein the information about the user includes a credential of the user, the credential associated with a smart card of the physical access control system, the smart card having been assigned to the user.
16 . The method of claim 15 , wherein the emulating of the transaction includes sending the credential to the reader over a secure connection in a format that is compatible with the physical access control system.
17 . The method of claim 13 , further comprising:
creating a logical association between the reader, the hardware accessory, and a client ID of the hardware accessory during a configuration phase, the creating of the logical association including simultaneously provisioning a public certificate, generating a private RSA key, and registering the client ID; and decrypting the JWE token using the private RSA key.
18 . A non-transitory machine-readable medium storing a plurality of instructions that, when implemented by one or more computer processors, cause the one or more computer processors to perform operations, the operations comprising:
receiving a soft token from a client device of a user, the soft token having been generated or received at the client device based on an accessing of a logical profile of the user by the client device via one or more services of a logical access control system, the soft token including a payload, the payload including information about the user that is stored in the logical profile, the soft token being a JWE token that is decrypted using a private RSA key stored in a secure element of a hardware accessory; based on a verifying of the soft token using a certificate extracted from a trust store of the hardware accessory, parsing the information about the user that is included in the payload; and based on the information about the user satisfying one or more access criteria of a reader associated with a physical access control system, triggering the reader, the triggering including emulating a transaction associated with the physical access control system.
19 . The non-transitory machine-readable medium of claim 18 , wherein the information about the user includes a role of the user.
20 . The non-transitory machine-readable medium of claim 18 , wherein the information about the user includes a credential of the user, the credential associated with a smart card of the physical access control system, the smart card having been assigned to the user.Join the waitlist — get patent alerts
Track US12556527B2 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.